The project includes tests, a README, and no install-time scripts. Release activity is sparse and there is no security policy, so maintenance assurances remain limited.
67%
Total Score
50
100
81
83
The package declares MIT, while its included LICENSE file is detected as LGPL-3.0. The release is licensed, but the mismatch creates a real adoption and compliance concern.
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package has only 3 releases across about 3 years, despite 2 releases in the last 12 months. This shows recent activity but a sparse overall release cadence.
One contributor made all 3 commits in the last 3 months. This concentrated activity leaves the project dependent on a single active maintainer.
The repository recorded 3 commits in the last 3 months, so it is active, though the volume is modest for a maintained library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.